rootpwn

Advisories

Citrix NetScaler ADC & Gateway CVE‑2023‑4966: Active Exploitation, Ransomware Threats, Immediate Mitigation Required

Citrix’s NetScaler ADC and Gateway suffer a critical flaw (CVE‑2023‑4966) that lets attackers hijack active sessions, bypass MFA and execute remote code. The vulnerability is already being exploited in wide‑scale ransomware campaigns. Affected versions include all 12.x, 13.x, and 14.x releases before the latest patches. Mandiant and CISA confirm active attacks. CERT‑FR urges zero‑delay patching, session termination, credential reset, and thorough forensic analysis. Ignoring the update leaves systems open to compromise.

Citrix’s NetScaler ADC and Gateway are under fire. A single flaw—CVE‑2023‑4966—has been assigned a 9.4 CVSS score and is already being weaponised by threat actors to hijack user sessions, bypass multi‑factor authentication, and run arbitrary code on vulnerable appliances.

What’s at stake?

  • Remote code execution and data exfiltration
  • Control over active user sessions, enabling lateral movement
  • Potential ransomware deployment through compromised gateways

Affected Software

  • NetScaler ADC & Gateway 12.x – prior to 12.1‑55.300
  • 13.x – prior to 13.0‑92.19 / 13.1‑49.15
  • 14.x – prior to 14.1‑8.50
  • FIPS and NDcPP variants follow the same version thresholds

Why the urgency?

“Exploit code is already in circulation, and ransomware campaigns are leveraging this vulnerability,” Mandiant warned on 17 October.

The U.S. CISA issued a security bulletin on 21 November, highlighting mass exploitation campaigns targeting this flaw. CERT‑FR’s update on 22 November stresses that any unpatched device should be treated as compromised and calls for immediate investigation.

Mitigation Steps

  • Apply the latest Citrix patch for CVE‑2023‑4966 without delay.
  • Terminate all existing sessions on affected gateways immediately.
  • Reset passwords for all accounts with gateway access.
  • Conduct a forensic review to detect any compromise indicators.
  • Monitor logs for anomalous session hijacking or MFA bypass attempts.

Next Steps

Security teams should reference Citrix’s security bulletin for patch details and follow the investigative guidance outlined by CERT‑FR. Staying ahead of the threat means patching now and tightening session controls.

CVE-2023-4966 Citrix NetScaler Ransomware Mandiant CISA CERT-FR

← All news